Which private IP class is it? The least common I have seen is B, which by default has a /16 mask. If your customer is paranoid and wants to have a scheme that is hard to guess, the class B is the way to go. If they use RIP version 1 as the routing protocol, they would have no choice but to use a /16, if they use a class B range, because RIP version 1 does not send subnet mask info in the updates.
Burt